Last Updated: 14/01/2026
Cloud 9 Assist Limited (“we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use the COHOAI platform (the “Service”).
1. Who we are (data controller)
Controller: Cloud 9 Assist Limited (registered in England and Wales, company number 08145753)
Registered office: 20–22 Wenlock Road, London N1 7GU, United Kingdom
Email: support@cloud9assist.com
Data protection contact: support@cloud9assist.com
2. Personal data we collect
We collect the following categories of personal data:
2.1 Information you provide
- Account details: name, email address, organisation (if provided), role/title (optional).
- Authentication data: passwords are stored in hashed form (we do not store plaintext passwords).
- Support communications: messages you send us and related metadata.
- Billing details: subscription status, invoices/receipts, and limited payment metadata (payments are processed by Stripe; we do not store full card details).
2.2 Information collected automatically
- Usage data: searches performed, companies viewed, saved lists/watchlists, and feature interactions.
- Device and log data: IP address, device/browser info, timestamps, pages viewed, error logs, and identifiers needed for security and fraud prevention.
- Cookies and similar technologies: see Section 8.
2.3 Public-record data displayed in the Service
The Service displays and processes Public Data from Companies House and other public sources. Public sources may include personal data (for example, names and roles of company officers or PSCs). We process this data to provide corporate research and due diligence features.
3. How we use personal data
We use personal data to:
- provide, operate, and maintain the Service;
- authenticate users and secure accounts;
- process subscriptions, billing, and customer support;
- personalise features (e.g., saved searches, watchlists);
- monitor usage, prevent abuse, and protect the Service;
- send service communications (e.g., account notices, security alerts, billing messages);
- improve and develop the Service (including debugging, analytics, and performance monitoring).
3.1 AI-powered features
The Service uses artificial intelligence (Google Vertex AI / Gemini) to provide features such as risk assessments, company analysis, and natural language search. When you use these features:
- Company data (from public sources like Companies House) may be processed by Google's AI services to generate insights.
- Your search queries may be processed to understand intent and improve results.
- AI-generated content is for informational purposes only and should not be relied upon as professional advice.
4. Lawful bases for processing (UK GDPR)
We rely on the following lawful bases, depending on context:
- Contract: to provide the Service you sign up for (account, authentication, subscription management).
- Legitimate interests: to secure the Service, prevent abuse, maintain logs, improve the product, and to process/display public-record corporate information in a way that supports due diligence and research (balanced against individuals’ rights).
- Legal obligation: to meet accounting/tax, compliance, or lawful request obligations.
- Consent (where applicable): for optional marketing communications or non-essential cookies/trackers (if used). You can withdraw consent at any time.
5. How we share personal data
We do not sell your personal data.
We may share personal data with:
- Payment processors (e.g., Stripe) to process subscriptions and payments;
- Hosting and infrastructure providers (e.g., Google Cloud) to run the Service;
- Analytics, monitoring, and security providers (e.g., error logging) to maintain reliability and prevent abuse;
- Professional advisers (lawyers, accountants) where necessary; and
- Authorities where required by law or to protect rights, safety, and security.
We require service providers to protect personal data and only process it on our instructions for the purposes described in this Policy.
Sub-processors and third-party services:
- Stripe – payment processing and subscription management
- Google Cloud Platform – cloud hosting, Firebase Authentication, Cloud Firestore database, and Cloud Functions
- Google Vertex AI / Gemini – AI-powered analysis and insights generation (company data may be processed by Google's AI services)
- Google BigQuery – data warehousing for industry benchmarking and analytics
- Companies House – UK public register for company information (we retrieve and display public data from this source)
- Resend – transactional email delivery for account notifications and alerts
6. International transfers
Your personal data may be processed outside the UK. Where we make “restricted transfers”, we use appropriate safeguards (such as recognised transfer mechanisms and risk assessments) as required by UK data protection law.
7. Data retention
We keep personal data only as long as necessary for the purposes described in this Policy, including:
- Account data: for as long as your account is active.
- Usage and log data: retained for security, troubleshooting, and improvement for up to 12–24 months unless a longer period is needed for investigations.
- Billing records: typically retained for 6 years to meet tax and accounting requirements.
- Backups: retained for up to 30–90 days and then overwritten.
You can request deletion of your account (see Section 9). Some data may be retained where required by law or for legitimate interests such as fraud prevention or dispute handling.
8. Cookies and similar technologies
We use cookies and similar technologies for:
- Essential functions (login/session, security, preferences); and
- Optional analytics to understand usage and improve the Service.
Where required, we will request consent for non-essential cookies and provide cookie controls.
9. Your rights
Under UK data protection law, you may have the right to:
- access your personal data;
- correct inaccurate personal data;
- request deletion (where applicable);
- restrict processing;
- object to processing (particularly where based on legitimate interests);
- data portability (where applicable);
- withdraw consent (where processing is based on consent).
To exercise rights, contact support@cloud9assist.com. We may need to verify your identity before acting on requests.
Self-service tools: You can delete your account and export your data directly from your Account Settings page. Account deletion is permanent and will remove all your personal data, including watchlists, saved searches, and preferences.
Important note on public-record data: if your request relates to correcting public-record information at source, you may also need to contact the relevant public body (e.g., Companies House). We will, where reasonable, refresh or update our records in line with source updates.
10. Complaints
If you have concerns, please contact us first and we’ll try to resolve them. You also have the right to complain to the Information Commissioner’s Office (ICO).
11. Security
We use appropriate technical and organisational measures to protect personal data. However, no system is completely secure and we cannot guarantee absolute security.
12. Children
The Service is not intended for children and we do not knowingly collect personal data from children.
13. Changes to this Privacy Policy
We may update this Policy from time to time. If changes are material, we will take reasonable steps to notify you.